CVE-2026-89551High· 7.0▾ TwilightA flaw was found in the Linux kernel's SUNRPC subsystem, specifically within the `xdr_buf_trim()` function. This vulnerability occurs when `xdr_buf_trim()` attempts to reduce the size of an XDR buffer. If the buffer's length is smaller tha…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 38.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 7.4
none → high
— → 7.4
none → high
— → 9.8
none → critical
9.8 → 7.4
critical → high
7.4 → 9.8
high → critical
0.2% → 0.5%
Last analysed / modified upstream
9.8 → 7
critical → high
A flaw was found in the Linux kernel's SUNRPC subsystem, specifically within the xdr_buf_trim() function. This vulnerability occurs when xdr_buf_trim() attempts to reduce the size of an XDR buffer. If the buffer's length is smaller than the amount being trimmed, an integer underflow can occur, causing the buffer's length to wrap to a very large value. This corrupted length then propagates to other XDR decoders, potentially leading to data misinterpretation and unexpected system behavior.
kernel: SUNRPC: xdr_buf_trim: clamp buf->len to avoid underflow — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-16.
Affected:
No fix planned:
Out of support scope
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-89476High· 7.0kernel: sctp: fix stream->outcnt underflow on duplicate RECONF responses (CVE-2026-89476)
CVE-2026-80936Medium· 5.5kernel: wifi: mt76: mt7925: cancel mlo_pm_work on stop (CVE-2026-80936)
CVE-2026-80947High· 7.0kernel: wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop (CVE-2026-80947)
CVE-2026-80980Medium· 5.5kernel: net/smc: stop killed, freed and out_of_sync sharing a byte (CVE-2026-80980)
CVE-2026-80981High· 7.0kernel: net/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link() (CVE-2026-80981)
CVE-2026-80985High· 7.0kernel: net/smc: carry oversized SMC-Rv2 LLC messages in the queue entry (CVE-2026-80985)